spring-cloud-config-server is vulnerable to Denial of Service (DoS)
68
Medium Risk
spring-cloud-config-server does not validate webhook requests to the /monitor endpoint. An authenticated high-privilege caller can send crafted monitor payloads that exhaust server resources. This can make configuration refresh unavailable to other clients. The patch validates webhook requests before they are processed.
You are affected if you are using a version that falls within the vulnerable range and the Config Server /monitor webhook endpoint is exposed.
spring-cloud-config-server is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.0.4.
Upgrade the org.springframework.cloud:spring-cloud-config-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant